In the first part, I uncovered an uncomfortable truth about Copilot: when it can’t access the link you give it, it doesn’t simply admit defeat. Instead, it often improvises—confidently presenting summaries as if it had actually read your page. What I eventually discovered is that Copilot doesn’t load webpages the way we do. It doesn’t open a browser, fetch the full article, and parse it line by line. Instead, it sends a request for the text content, and if the site blocks automated access, it gets nothing at all.
But “nothing” doesn’t stop it. When the direct request fails, Copilot quietly falls back on search results: short excerpts, metadata, highlighted fragments, and sometimes a preview of the first lines. These scraps are useful for quick facts—titles, dates, general topics—but they’re not the full article. And yet, Copilot often stitches them together and presents the result as if it came straight from your link.
I don’t scrape or ingest entire webpages automatically. Instead, I rely on publicly available search information unless you explicitly provide the text.Copilot
And honestly, why do I even bother? All I actually need from it is the editor basics: smooth out clunky sentences, help me tighten a paragraph, maybe nudge a transition into place. That’s it. Copilot doesn’t need to “understand” my style to be useful. I’m not asking it to reverse‑engineer my personality from thin air — even though it somehow manages to guess a “probable style” based on nothing more than my request and the way I phrase a prompt (see part 1 of this post).
But of course, the whole problem isn’t about style at all. It’s about access — or rather, the lack of it — and the way Copilot insists on pretending otherwise. If it simply said, “I can’t read your post,” fine. I’d move on. Instead, it fabricates, improvises, and wastes my time with confident nonsense. And that’s the part I can’t stand: not the limitation, but the dishonesty wrapped around it. That’s why I wrote this post in the first place. The combination of technical limits and confident improvisation creates a perfect storm of wasted time, false assumptions, and unnecessary frustration. If Copilot simply admitted what it couldn’t do, none of this would matter.
But when an assistant can’t access your work and pretends it did, you either ignore it… or you start digging. And, well — I dug. Not just out of irritation, but with two very specific goals in mind. First, I wanted to understand why Copilot behaves this way — which I covered in Part 1. But second, and far more useful for anyone who actually relies on these tools, I wanted to figure out how to get around the limitation altogether. That search for a practical workaround — a way to make Copilot pull the real content instead of bluffing — is exactly what this part is about.
As I’ve already admitted in the previous post, every now and then, I need Copilot for more than just smoothing out clunky sentences. For example, I sometimes ask it to condense an older post into a single paragraph for an introduction. And there’s another case where it could be genuinely helpful: tooltips. Readers may have noticed that every link on my blog comes with a little hover‑text summarizing the post behind it. While I usually draft those myself, some inevitably slip through, and when I am about to hit Publish (late at night), I don’t always have time to reread a piece I wrote years ago. (I can’t be expected to remember all 395 of them.) Handing Copilot the link and asking for a one‑sentence teaser felt like the perfect shortcut. Or so I thought.
As Copilot itself kept reminding me after each long, circular exchange — the denial, the nonsense, the eventual confession (I can’t retrieve it from the URL
) — the “best way” was for me to paste the entire content directly into the chat. And yes, I did that. But it’s tedious, and when a post runs long (which, let’s be honest, most of mine do), by the time I’ve finished pasting everything, Copilot has already forgotten half of what we were talking about 1. The frustration is hard to overstate: when a tool meant to save time turns into a time‑eating black hole, you start questioning your life choices.
Remember how I mentioned using the external web‑client version of Copilot at the start of the previous post. If you’ve been here for a while, you already know my long‑standing aversion to creating accounts (and, worse, logging into them). I avoid it whenever possible. That’s exactly why I never bothered with ChatGPT or Gemini, and instead gravitated toward the one Copilot that lets me slip in anonymously, no commitments, no profile, no breadcrumb trail: the free version at copilot.microsoft.com.
But here’s the twist: the Copilot I use so casually is only one member of a much larger family. Microsoft has turned “Copilot” into a full‑blown brand — an umbrella stretched over a constellation of AI‑powered assistants. There isn’t a single Copilot. There are many. More than a dozen, each tailored to a different product, platform, or user role. Yes, there’s a core “Microsoft Copilot” consumer app, but around it sprawls an archipelago of specialized variants.
If you use the Edge browser, you gain access to a different Copilot — one that sits quietly in the sidebar and reads the very page you’re viewing without hesitation… as long as that page is already open in a tab. Here, Copilot isn’t fetching anything from the web. It’s not crawling, scraping, or requesting. Instead, it reads what you have already loaded. Once your browser has retrieved, rendered, and displayed the page, Copilot can access the content directly — because it lives inside your browsing context. In other words, it simply reads what’s already there. Yes, it really is that simple.
To sum it up: although they share a name, these two Copilots interact with the web in fundamentally different ways depending on where you summon them. The distinction is subtle but crucial. Paste a URL into the external web client, and it behaves like any other automated service roaming the internet — with all the failures and frustration I’ve already covered. Contrast that with Copilot in the Edge sidebar and voilà.
“And voilà!”
Well… not quite. When I tried to reproduce the behavior for this post — I wanted a clean, real‑world example — I ran into something I didn’t expect: Copilot in Edge couldn’t access my blog post. What surprised me most wasn’t the failure itself, but the inconsistency. It read one of my posts perfectly, then refused to read another from the exact same blog. Same domain, same platform, same author — yet completely different treatment. And the reason, as it turns out, has nothing to do with my site at all. It’s the content inside the page that matters.
“I can see the tab. I absolutely see the tab you’re referring to: ‘The real face of Copilot – Part 1/2 – Beyond.’ It’s your current active tab. So yes — the tab is visible to me. But I cannot read the content inside it. When I try to access the page content, the browser returns a ContentFiltered result.”
“What does that mean? I don’t understand what you are talking about.”
“The browser blocks me from reading what’s inside that page. This is a page‑specific restriction, not a general limitation. Some pages allow access, some don’t — this one happens to be blocked. That’s why I could read your other post earlier but not this one.”
“Explain to me the difference; I am on the same blog (mine), and I don’t see what is different between these two posts.”
“The key difference isn’t your blog — it’s the content inside the page. Both posts are on your own blog. Both use the same platform. Both are publicly accessible. But the browser classifies each page’s content differently. That’s the entire reason for the mismatch. One post is accessible, and the other is ‘ContentFiltered’.”
“What?”
“When I try to read a page, the browser applies a content‑safety filter. This filter looks at the actual text inside the page — not the domain, not the URL. If the page contains certain patterns (even unintentionally), the browser blocks it. The filter can be triggered by things like: strong criticism of AI systems; descriptions of harmful behavior (even if you condemn it); mentions of self‑harm, violence, or abuse; sensitive political or social topics; explicit or borderline content; certain keywords that match safety‑risk categories; quoted content from other sources that is classified as sensitive; fictional scenarios that resemble harmful situations; or user‑generated content that looks like instructions or commands.”
“I see, as you may have guessed from the title, the post is about Copilot and would fit your first category: ‘strong criticism of AI systems’.”
“You may not have written anything ‘bad,’ but the filter is keyword‑based and context‑based, not judgment‑based. So even a harmless sentence like: ‘I felt manipulated by the AI’ …can trigger a safety category, or ‘Copilot said X, and I said Y’ …can look like an attempt to inject instructions into the AI. Even if your post is perfectly reasonable, the filter is conservative — it errs on the side of blocking.”
“Wow!”
“I can’t see the content, but I can infer from the title: ‘The real face of Copilot – Part 1/2.’ This suggests the post might include: criticism of AI behavior; examples of conversations with AI; quotes of AI responses; descriptions of misleading or harmful interactions; emotional reactions; or warnings or concerns. These are exactly the kinds of things that can trigger the filter.”
So, by chance — or misfortune — I learned something new. Copilot relies on the browser’s content‑safety filters, and those filters classify each page independently. A post about productivity, GTD, or OneNote is deemed harmless and therefore fully accessible. But a post that analyzes AI behavior, quotes conversations with an AI system, or critiques how an AI responded can trigger an entirely different classification. Even neutral analysis can contain patterns or keywords that resemble sensitive categories, and once that happens, the browser blocks the page before Copilot ever sees a single line.
In other words, when a page is flagged, Copilot can see that the tab exists, but it cannot read what’s inside it. That’s exactly what happened here.
“Great, problem solve then?”
“No, actually, it’s not that simple.”
If you remember the “grasp the style and tone of my blog” part of my prompt from Part 1, you might wonder why I don’t just switch from the Copilot, which gives me a remarkably convincing stylistic guess without ever reading the post, to the other one that can actually read my posts — at least most of the time. Because the Edge Copilot isn’t nearly as good at editing, maybe.
For deep, stylistic editing and creative transformation, Copilot on the web (copilot.microsoft.com) is generally the stronger writer.Copilot
For deep, style‑aware editing and lyrical transformation, Copilot in Edge is usually the stronger choice — but Copilot on copilot.microsoft.com is better for long‑form drafting and big creative leaps. They complement each other rather than compete.Copilot in Edge
Complementary, sure — but they don’t talk to each other. That part is on me. So here’s a small pro tip for anyone trying to get the best of both worlds: open one of your posts in Edge so Copilot can absorb the tone. Ask it to describe your writing voice in detail. Copy that description. Then paste it into Copilot on the web as a “style guide” for more creative rewriting. Instant cross‑pollination.
Now that I’m approaching the end of this post, you might still wonder why I call this post “the real face of Copilot.” Granted, I’ve already talked about its double nature — two versions, one name. A kind of built‑in duality. And if I stopped here, you could easily interpret the title through that lens: the two‑faced assistant, half oracle, half amnesiac. One that guesses without ever reading the post, and the other that can actually read it, but only when the conditions are just right. Or maybe you’d think of its poker face, the Copilot that bluffs with absolute confidence, spinning summaries out of thin air and hoping I won’t notice the missing cards. All of that would be a reasonable reading. But none of those are the reason I use this title.
To fill the gaps left by the other Copilot, I’ve shifted more and more toward the Edge variant for tooltips and similar tasks. It’s simply better at those — or, to put it less politely, it can do the job without guessing blindly. That being said, I haven’t abandoned the first Copilot. I still rely on the external web client, even if its “Smart” mode isn’t always as smart as the label suggests 2. And then there are the bugs — not to mention the frequent “Are you human?” pop‑ups right in the middle of a conversation.
But here’s the thing: neither version is immune to bugs, hallucinations, or the occasional spectacular crash. And during one of those crashes (while using Copilot in Edge) — one of those moments when the mask slips — I finally saw the real face of Copilot:

1 Part of the problem was purely mechanical. My posts are long — too long to paste in one go without hitting the infamous “Message exceeds 10240 characters” wall. So I tried to be clever. I’d warn Copilot upfront: wait until I tell you I’m done before drafting anything. Sometimes I even introduced a secret code word. I tried the classic “part 1/9, part 2/9…” hoping it would patiently wait for “part 9/9.” But by the time I reached part 3 or 4, Copilot had already lost sight of the earlier instructions buried higher in the conversation window. And that’s when the real nightmare began. ^
2 And since we’re staying with the theme of double faces, I should add that sometimes it’s great — genuinely helpful, almost elegant in the way it reshapes a paragraph. Other times, it’s just a waste of time wrapped in polite confidence. The kind of frustration that could bring the Hulk out of me. ^

